GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,043
Maven
5,000+
npm
4,781
NuGet
825
pip
4,382
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
26,440 advisories
Filter by severity
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route
High
CVE-2026-27730
was published
for
github.com/esm-dev/esm.sh
(Go)
Feb 25, 2026
Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline
Critical
CVE-2026-27739
was published
for
@angular/ssr
(npm)
Feb 25, 2026
Angular SSR has an Open Redirect via X-Forwarded-Prefix
Moderate
CVE-2026-27738
was published
for
@angular/ssr
(npm)
Feb 25, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure
High
CVE-2026-27616
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
RustFS: Missing Post Policy Validation leads to Arbitrary Object Write
High
CVE-2026-27607
was published
for
rustfs
(Rust)
Feb 25, 2026
Rollup 4 has Arbitrary File Write via Path Traversal
High
CVE-2026-27606
was published
for
rollup
(npm)
Feb 25, 2026
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method
Critical
CVE-2026-27699
was published
for
basic-ftp
(npm)
Feb 25, 2026
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
Moderate
CVE-2026-27729
was published
for
@astrojs/node
(npm)
Feb 25, 2026
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service
Moderate
CVE-2026-27695
was published
for
zae-limiter
(pip)
Feb 25, 2026
n8n Vulnerable to Stored XSS via Various Nodes
High
CVE-2026-27578
was published
for
n8n
(npm)
Feb 25, 2026
n8n: Expression Sandbox Escape Leads to RCE
Critical
CVE-2026-27577
was published
for
n8n
(npm)
Feb 25, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
Critical
CVE-2026-27575
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
Vikunja has Reflected HTML Injection via filter Parameter in its Projects Module
Moderate
CVE-2026-27116
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
n8n has Arbitrary Command Execution via File Write and Git Operations
Critical
CVE-2026-27498
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Potential Remote Code Execution via Merge Node
Critical
CVE-2026-27497
was published
for
n8n
(npm)
Feb 25, 2026
n8n has a Sandbox Escape in its JavaScript Task Runner
Critical
CVE-2026-27495
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
High
CVE-2026-27494
was published
for
n8n
(npm)
Feb 25, 2026
n8n has Unauthenticated Expression Evaluation via Form Node
Critical
CVE-2026-27493
was published
for
n8n
(npm)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute
Moderate
CVE-2026-25736
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name
Moderate
CVE-2026-25735
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata
Moderate
CVE-2026-25734
was published
for
rucio-webui
(pip)
Feb 25, 2026
Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting
High
CVE-2026-3105
was published
for
mautic/core
(Composer)
Feb 25, 2026
ImageMagick has a heap Buffer Over-read in its DJVU image format handler
Moderate
CVE-2026-27799
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images
Moderate
CVE-2026-27798
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
hexchat crate has a Use After Free vulnerability
High
GHSA-x43w-ph7m-pfjx
was published
for
hexchat
(Rust)
Feb 25, 2026
ProTip!
Advisories are also available from the
GraphQL API